CVE Vulnerabilities

CVE-2024-23159

Use of Uninitialized Variable

Published: Jun 25, 2024 | Modified: May 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Weakness

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Affected Software

Name Vendor Start Version End Version
Autocad Autodesk 2022 (including) 2022.1.5 (excluding)
Autocad Autodesk 2023 (including) 2023.1.6 (excluding)
Autocad Autodesk 2024 (including) 2024.1.5 (excluding)
Autocad Autodesk 2025 (including) 2025.1 (excluding)

Potential Mitigations

References